Summary
- Attackers stopped a steam turbine and water-treatment system at a Polish combined heat and power plant during the December 2025 energy-sector campaign.
- CERT Polska traced access into the OT environment through a private APN whose configuration allowed devices expected to be separated to communicate.
- Plant operators restored the installation before customers lost heat, containing the public consequence of a destructive industrial intrusion.
A destructive cyberattack on a Polish combined heat and power plant stopped a steam turbine and water-treatment system after attackers found an unexpected route into its operational technology network, according to a new investigation by CERT Polska.
The plant supplies heat to around 50,000 residents and was attacked on 29 December 2025, during the same coordinated campaign that targeted 30 wind and solar installations and another combined heat and power facility in Poland. The second plant had not previously been disclosed publicly.
CERT Polska said the intrusion stopped the plant’s steam turbine and the system used to produce process water, interrupting cogeneration. Operators responded quickly enough to limit the outage and restore the installation before heat supplies to customers were disrupted.
The investigation took more than three months and reconstructed an access path involving a private access point name, or APN, used to connect remote infrastructure over a mobile network. CERT Polska said this was, to its knowledge, the first observed real-world cyberattack in which a private APN had been used as a route into an OT environment.
The attack was possible partly because devices inside the private APN were allowed to communicate with one another. That undermined the degree of isolation expected from the arrangement and allowed an attacker with access to one connected environment to reach further into infrastructure on the same private network.
CERT Polska said surveys of organisations using comparable configurations suggested the arrangement was common in Poland and believed similar deployments existed elsewhere. It has published recommendations for organisations relying on private APN-based connectivity alongside its incident report.
The finding broadens the significance of the incident beyond one heat plant. Private cellular networks are widely used where industrial operators need to connect geographically dispersed assets without conventional fixed infrastructure, including energy, utilities, transport, and other operational environments.
The security of those connections depends on more than whether they are isolated from the public internet. Internal communication rules, identity, routing, device configuration, and the paths available between connected assets can determine whether compromise of one endpoint exposes systems that were assumed to sit behind a separate trust boundary.
The Polish incident also demonstrates how operational resilience can constrain the effects of a successful destructive attack. The attackers reached systems with direct physical functions and stopped parts of the cogeneration process, yet the plant’s response prevented the cyber event from becoming a sustained loss of heat for residents.
That distinction is increasingly relevant as European cyber requirements extend deeper into operational technology, remote access, supplier dependencies, and continuity planning. Preventing intrusion remains one part of resilience, but energy operators also need processes that allow essential services to continue when digital controls have already failed or been manipulated.
The report leaves some elements of the original access unresolved, including precisely how one router password was obtained. CERT Polska nevertheless reconstructed the route through the private network and the attacker’s subsequent activity with enough confidence to identify a configuration pattern that may exist beyond the affected organisation.
The December campaign was already notable as a coordinated destructive operation against Polish energy infrastructure. The additional plant shows that its reach and technical paths were broader than initially understood, while the absence of customer disruption owed more to operational recovery than to a lack of attacker access.



